Category Archives: For Business

SECURITY ALERT: GermanWiper Ransomware Erases Your Data Even If You Pay

German companies and employees of German companies, in particular, are faced with a devious wave of ransomware attacks. While the new ransomware strain has been targeting mostly German victims so far, there’s no telling how far it may spread. We should all be aware of how the ransomware infects devices and how it works.

The GermanWiper ransomware earned its name not just because of the German focus of its intended targets, but also because it’s particularly devious. It doesn’t really encrypt data with a secret key, like other ransomware, awaiting payment in order to decrypt it.

With this one, there’s a nasty twist. The GermanWiper ransomware overwrites the data with strings of zeroes, rendering it completely unusable (wiped) forever. Nevertheless, it still acts like typical ransomware, falsely promising the victims that their files will be back if they pay a fee.

How Does the GermanWiper Ransomware Spread?

The victims of the GermanWiper ransomware typically receive a German-language email on behalf of a phony job applicant. The spam email pretends to be from a certain Lena Kretschmer, who is looking for a job and is sending the target a job application.

This is how the typical GermanWiper email looks like:

germanwiper spam email

The common subject line of the email is “Ihr Stellenangebot – Bewerbung [Your job offer – Application] – Lena Kretschmer“. If the target opens it, they will notice that the email also contains an attachment named “

If the victim makes the mistake of opening the zip archive, they will then get what looks like PDF files (with the correct file extension, .pdf). The files are actually link files (LNK) masquerading as PDF files, and once opened they will begin running malicious commands on the machine, infecting it.

When the LNK files are opened, they execute a PowerShell Command which downloads a malicious HTA file from xpandingdelegation[.]top site (domain sanitized for your safety). The HTA file then downloads the main ransomware executable. It all takes place in a matter of seconds. So, once you open those fake PDF files, there’s no turning back.

What Happens Once Infected with the GermanWiper Ransomware

There are two types of ransomware, usually: file lockers and computer (or device) lockers. The first (and more common) just lock your important data with a secret encryption key. The second type renders your device as a whole unusable until the ransom is paid.

GermanWiper is the type which only locks the files, so it’s less severe than the ones which block any use of your device. But unlike file lockers the world has seen so far, GermanWiper doesn’t lock anything. It only claims to have locked (encrypted) your files.

What it actually does is rewrite them with zeroes, such as in the screenshot below:

germanwiper wiped file

Image source: BleepingComputer.

If you were so inclined to pay the required ransom, there’s no doubt it would be for nothing. We haven’t heard from people who fell for the scam so far, but since the files are actually rewritten with zeros, it’s clear that there is nothing to recover.

If you are in this situation and find yourself infected with GermanWiper, there’s nothing to do. Just count your losses and have a better protection system in place next time. Company-wide cybersecurity awareness training is also a must.

What to Do If Infected with Ransomware

Even though there are plenty of free ransomware decryption tools which can help victims of ransomware, in many cases there is nothing to do but pay the attackers.

I personally wouldn’t recommend it because this keeps feeding the malware economy. Unless the data you lost is a matter of life-and-death, if you can’t decrypt it just let it go. Don’t repay the attackers for their unethical work.

Still, I won’t judge if you do decide to pay the ransom in order to get your data back. Unfortunately, as mentioned above, payment is not an option with the GermanWiper ransomware. This malicious creation will just delete your data from the start, so even if you send the ransom money, you can’t get it back. It’s just falling for a scam.

Of course, the best way to not get infected with ransomware (and other malware in general) is prevention. Adopt a proactive stance to your online security and you’ll be safe instead of sorry.

Against new strains of ransomware such as this one, Antivirus is not enough. You also need a DNS traffic filtering layer on top, which is able to detect even unknown malware. Our flagship product, Thor Foresight Home, is an award-winning product exactly for this type of challenge. If you’d like to try it out, here’s one month on the house.

The easy way to protect yourself against malware
Here's 1 month of Thor Foresight Home, on the house!
Use it to: Block malicious websites and servers from infecting your PC Auto-update your software and close security gaps Keep your financial and other confidential details safe


Try Thor Foresight

Be vigilant and don’t open attachments in emails, no matter how legit they seem. If you’re located in Germany and receive a work proposal email, be extra-extra cautious. It may be GermanWiper looking for its next victim.

The post SECURITY ALERT: GermanWiper Ransomware Erases Your Data Even If You Pay appeared first on Heimdal Security Blog.

Windows Defender Vulnerabilities: How the Latest Malware Can Disable It

Are you relying only on the built-in defenses in your Windows 10 operating system for security? This was never a good idea, but lately, it became even more dangerous. Windows Defender vulnerabilities were uncovered by researchers, far surpassing what users could have expected.

During the past months and even before that, the world of cybersecurity has held its breath over Trickbot updates. The banking Trojan has been around since 2016 and according to recent forensics of it, it has compromised over 265 million email accounts. While the malware is not exactly new, the trickiest part about it (pun intended) is how it manages to adapt.

The most worrisome part of its evolving trajectory is its ability to disable Windows Defender. The latest cybersecurity analysis has revealed that in its latest campaign, Trickbot has been targeting Windows 10 users. Especially in corporate environments (but also inside plenty of home devices), this is the operating system of choice.

How Does Trickbot Work?

Trickbot has been around since 2016 and managed to be a stressful threat ever since. Targeting both individuals and companies, it is a jack of many trades. Every time security has it pinned down and think that a permanent counter has been found, Trickbot resurfaces in an altered form.

Thor Foresight makes sure that link is safe!
Your parents and friends will click any suspicious link, so make sure they're protected.
Thor Foresight Home anti malware and ransomware protection heimdal security
Thor Foresight provides: Automatic and silent software updates Smart protection against malware Compatibility with any traditional antivirus.


Get Thor Foresight

This is not about the usual change all malware strains go through to evade detection by simple Antiviruses. Generally, malware developers (hackers) change just a few lines of code to make the malware appear different.

Trickbot’s History of Adapting to Defensive Software

Not so with Trickbot. In this case, whenever Trickbot got reinvented, it also resurfaced with a changed strategy. That’s the main reason for which it wasn’t yet completely eradicated. At the moment, small businesses are the most endangered by Trickbot’s activity.

Over its 3 years of activity, Trickbot wore many disguises and targeted various entities and systems, depending on what was deemed more vulnerable at the time. When it first emerged, it seemed to borrow heavily from Dyrezza, a previous banking Trojan. It also stole data from users via malicious spam.

From its initial emergence, Trickbot proved to be impressively adaptable. It changed tactics from scam emails sending warnings about unpaid bills to account update phishing emails. It could propagate either through infected URLs and malicious email attachments.

How Trickbot Operates Now

Once it manages to infect one endpoint, Trickbot quickly spreads through the entire organization, laterally. The malware uses an SMB vulnerability to propagate. It’s then notoriously difficult to detect (it requires network admins to intuitively guess something is wrong, just by monitoring traffic and resource footprints).

Trickbot is even more notoriously difficult to remove, once detected. It requires IT admins to manually go through every infected endpoint, isolate it, and clean it.

Unfortunately, because Trickbot spreads through the SMB vulnerability, any sanitized endpoint can quickly become re-infected once it joins the network again if there is at least one other infected machine.

It also becomes more persistent by creating Scheduled Tasks, which carry out its agenda while evading user (and security software) detection. This makes the clean-up process painstaking and the infection incredibly resilient.

How Can Malware Disable Windows Defender?

Advanced malware has gained ways to avoid being detected by Windows Defender, in the past few years. This isn’t really news. What makes Trickbot exceedingly dangerous is the way it is capable to not only fly under Windows Defender’s radar but disable it altogether.

In one of the most recent Trickbot developments, the malware surprised researchers by silently disabling Windows Defender. Once the default protection was out of the way, the malware then proceeded to carry out its agenda of data stealing and email compromising.

In its most recent data scraping, it’s estimated that over 265 million email addresses were exposed and compromised. These emails will now be used in phishing and scamming campaigns, poised to break into banking accounts and make away with funds.

Here is how Trickbot exploits Windows Defender vulnerabilities:

At the time of my writing this blog post, this is how the most recently detected Trickbot version behaves, as documented by MalwareHunterTeam and Vitali Kremez.

Step #1. Add policies to SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection for the following:

  • DisableBehaviorMonitoring: Disables behavior monitoring in Windows Defender.
  • DisableOnAccessProtection: Disables scanning when you open a program or file.
  • DisableScanOnRealtimeEnable: Disabled process scanning.

Step #2. Configures the following Windows Defender preferences via PowerShell:

  • DisableRealtimeMonitoring: Disables real-time scanning.
  • DisableBehaviorMonitoring: Same as above, except as a Windows Defender preference.
  • DisableBlockAtFirstSeen: Disables Defender’s Cloud Protection feature.
  • DisableIOAVProtection: Disables scans of downloaded files and attachments.
  • DisablePrivacyMode: Disables privacy mode so all users can see threat history.
  • DisableIntrusionPreventionSystem: Disables network protection for known vulnerability exploits.
  • DisableScriptScanning: Disables the scanning of scripts.
  • SevereThreatDefaultAction: Set the value to 6, which turns off automatic remediation for severe threats.
  • LowThreatDefaultAction: Set the value to 6, which turns off automatic remediation for low threats.
  • ModerateThreatDefaultAction: Set the value to 6, which turns off automatic remediation for moderate threats.

All the measures taken by Trickbot to make sure it can carry out infections undisturbed are meticulous and complex. It’s easy to see how easy it would be for most users to be unaware of anything wrong until it’s too late. After all, who manually checks the permissions in Windows Defender daily?

Other Malware Which Disables Microsoft Security Apps

Perhaps even more worrisome is that Trickbot seems to not be an isolated case. We’re not dealing with brilliant hackers, the likes of which the world has never seen. The disabling of built-in defenses is becoming a more and more common sight with the latest malware strains.

The most recent example is the DealPly adware, which turns off defensive software such as Microsoft Smartscreen, but also well-known commercial security software (McAfee’s WebAdvisor). The actual damages of DealPly are not severe yet, but even malvertising can have disastrous effects when paired with financial malware and others.

Even if the damages of the DealPly adware are not immediately visible at this moment, it’s nevertheless worrisome how it can disable security software. Apparently avoiding detection will remain a malware ambition of the past.

We’re likely heading into an era of third-gen malware, if I were to speculate.
Click To Tweet

More Windows Defender Vulnerabilities to Know about

All Windows Defender vulnerabilities can be checked in almost real-time on a dedicated CVE portal HERE. You can also check for fixes there, but be warned that it can be a hassle to do it manually.

Windows Defender Updates Which Are Somewhat Closing Vulnerabilities

To be fair, Microsoft is trying to patch some of these vulnerabilities and succeeds to close gaps somewhat. But in the long run, especially because Microsoft is a huge target of attackers worldwide, it’s impossible to stay afloat.

How to Stay Safe Beyond the Limited Protection of Windows Defender

Within the limited scope of built-in Windows defenses, what you can do is create a separate user account. Run most of your routine activities from this plain user account and only enter the administrator account when you need to do something very important. Even then, tread carefully.

The other thing to do in order to overcome the Windows Defender vulnerabilities is to invest in extra protection layers.

You clearly can’t rely on Windows Defender for keeping your PC or laptop safe. Not having a specialized cybersecurity suite to protect your device has always been a hazard. But now, with the recent developments, it’s revealed to be even more dangerous than previously thought.

My advice is to not postpone your cybersecurity or stick to the free, default versions such as Windows Defender. No matter how improbable you might think a malware infection is, it may be closer than you think. People who lost data, money, privacy or worse to malware all thought it couldn’t happen to them.

Don’t rely on built-in, default defenses, or on a single security product, for that matter. Stay vigilant and try to have solutions which keep up with the threatscape.

How much protection is enough?

In the cat and mouse cybersecurity game, hackers quickly find ways to overcome current defensive software. Then, the defensive software strives to redefine itself to overcome the new malware developments, and so on.

All this takes place with exhilarating speeds. So, to make sure you can’t become the next victim of malware, don’t stop at one defender. Have an active next-gen Antivirus, but also a threat detection layer on top of it. Also, update your software and apply patches as soon as they’re released.

A cybersecurity suite which contains all of the above is, of course, ideal, so I can recommend our Thor Premium Home. If you want to try it for free, here’s a month on the house. Just click on the ‘I want to try it free for 30 days’ option and follow the rest of the instructions for installing.

Final thoughts

Regardless of the brand of products you use, just know that you’re better off using at least something in addition to just Windows Defender. Preferably, your defenses should include a smart threat detection mechanism, like a DNS filter. As long as you do that, all should be well.

Good luck with your cybersecurity and don’t forget to check from time to time if your Windows Defender is still active and up to date. Check especially if you’re not 100% confident in the rest of your security software. If you stay vigilant, you may catch threats in time, before any significant damage is done.

The post Windows Defender Vulnerabilities: How the Latest Malware Can Disable It appeared first on Heimdal Security Blog.

What Is Spear Phishing and How Do You Prevent It?

There’s more than one way to catch a ‘fish’ than phishing. And because the world of hacking always delivers when it comes to wacky wheeling-and-dealing, in this article I’ll be talking about spear phishing attacks. What is spear phishing, you ask? Long story short, it’s a phishing technique that plays on the victim’s trust or, rather his gullibility.

Spear phishing attacks are surgical, while general phishing attacks are more like “let’s cast this lure in the puddle and see what bites.” So, without further ado, let’s dig right into it. FYI: in this article, I’ll be covering the difference between spear and whale phishing and how to protect your company’s digital assets against them.

What is Spear Phishing?

So, what is spear phishing? According to the Big Book of things that go bump on the Internet and can really ruin your day, spear phishing is an email spoofing attack that targets very specific and very ‘employed’ individuals. As Aaron Ferguson noted, spear phishing attacks are directed against an employee or an organization.

What makes them so successful? Good question! Ferguson, an NSA agent and West Point Professor, said that the spoofed emails used in the attack look like they’ve been sent by well-known market actors such as PayPal, Google, Spotify, Netflix, and even Apple Pay.

In some cases, they make even take the guise of in-house emails, asking the employee to fill in credential requests. Why would someone be willing to share his/her credentials via email? Well, think of it this way: how likely are you to nix an email from your CEO, asking you ‘nicely’ to share your password and user because you’re far behind on your deadlines?

To further enforce the illusion, these spoofed emails use the moniker of an authoritarian figure (CEO, CTO).

And yes; the unaware user will click on any link, share any details, no matter how private they are, and will go on thinking that he dodged another bullet. Unfortunately, that reply will never reach your boss; it will end up in some hacker’s database who will have complete access to the company’s records.

Still, why is spear phishing that successful? Because the ‘spoofer’ really does his homework. Before a spear phishing’s attempt been made, the attacker will try to gather as much info as he can about his victim: name, work address, company’s profile, position, phone numbers, emails. When he has enough info, he will dispatch a cleverly penned email to the victim.

Thor Foresight makes sure that link is safe!
Your parents and friends will click any suspicious link, so make sure they're protected.
Thor Foresight Home anti malware and ransomware protection heimdal security
Thor Foresight provides: Automatic and silent software updates Smart protection against malware Compatibility with any traditional antivirus.


Get Thor Foresight

An unlikely affair?

To show you just how effective these attacks are, I’m going to quote Ferguson’s example. Oh, by the way: successful spear phishing attacks are also called the ‘colonel effect.’ You’ll figure out in a sec why they’re called that way.

So, Ferguson, who’s also a West Pointer, wanted to find out just how knowledgeable the cadets are when it comes to cybersecurity. The teacher sent out some 500 emails to his students, but they appeared to have been sent by a certain Colonel Robert Melville from the same academy. In these emails, the ‘colonel’ wrote that the cadets can peek at their exam’s results by clicking on the enclosed link.

Naturally, nothing happened if they clicked the link. Instead, they would receive a follow-up message reading: “you have been spoofed. During this time, your computer could have been infected with trojans, viruses, or ransomware.” Seems like a harmless enough experiment, but the numbers paint an entirely different picture:  80% of cadets clicked on the bogus link.

Lesson learned – we still know squat about cybersecurity.

Spear Phishing vs. Whale Phishing

Source: IT-seal

There’s a huge difference between spear and whale phishing. While the first targets the ‘weakest link’ the latter is aimed at the big chief himself. Whale phishing attacks are designed to siphon confidential info from high-profile individuals such as chiefs of staff, C-level executives, celebrities, politicians, senior officers etc.

The technique’s more or less the same – spoofed emails sent from trusted sources. Still, compromising a high-profile target isn’t as easy as stealing data from a gullible employee. In this case, the attacker will also employ some social engineering tricks in an attempt to gather intel on his target.

Probably the best whale phishing example is the 2016 Seagate affair. Yes, the very same company that’s ‘responsible’ for your Barracuda hard drive had a major data breach three years ago after an HR officer sent out copies of employees’ 2015 W-2 tax forms, as requested via email by CEO Stephen Luczo.

Thinking that the email came straight from the “horse’s mouth”, the HR sent out the tax records copies. You can very well imagine what happens when someone shares very sensitive financial info on some 10,000 employees. Anyway, once upper management got wind of this data leak, they notified the authorities. No word so far on what became of the stolen data or the person(s) behind this attack.

Whale phishing attacks are more common then you think. During the same year, two other whaling attacks occurred – one of them involved Evan Spiegel, Snapchat’s CEO, and FACC, a plane manufacturing company that ‘incidentally’ works for Airbus and Boeing.

Phishing with a…rose

A bit on the poetic side, but rose phishing does exist although it’s not as as common as regular or spear phishing. It does sound rather outré, yet this type of scam has been around since like forever. Remember the ploy with the sickly father/uncle/brother and someone reaching out for cash? It’s basically the same thing; the only difference being that everything’s done online.

So, how does this work exactly? Well, let’s assume for a moment that a hacker wants access to your PayPal account. Bear in mind that rose phishing is  taking the high road, lots of cloak-and-dagger stuff.

Now, the hacker will first attempt to gather as much info as possible about you: tastes in music, clothing, favorite hangout places, and, most importantly, friends. After the ‘recon’ phase, the hacker will then try to get in touch with your close friends, posing as a distant relative, high school crush, or whatever. Of course, he’s not even remotely interested in establishing a rapport with any of them; he’s just looking for a way to reach you.

What does happen once the scammer gets in touch with you? Well, he will do everything to earn your trust. And when I say “everything”, I mean just that. Some are pretty good – sharing their sob life experiences, others may even say they fell in love.  Once they gain your trust, they will ask for some sort of favor – like my Facebook page (which is obviously spoofed), ask for a small loan, donation, or whatever. And we both know how this story ends, don’t we?

Spear Phishing IRL

Source: Easy Sol

And because no great piece of writing should be without some good stories, here’s what I managed to scrape up on spear phishing. Enjoy!

1. Alcoa

For those of you unfamiliar with the name, Alcoa’s is one of the world’s biggest producers of aluminum. With a business that spans 10 countries, the company makes for one tantalizing trophy. And, as fate would have it, then one who cracked open Alcoa’s treasure trove of industrial secrets was…the Chinese military.

Yes, I know that it sounds like something out of a James Bond movie, but the facts stand true. So, in 2008, a group of hackers hired by the Chinese military send out some 5,000 spoofed emails to various Alcoa employees. Without even flinching, all employees opened the email upon receival.

They didn’t click any links – once the recipient opened the email, the malware was installed on the computer. A couple of seconds later, the company’s closely-guarded secrets fell into the hands of the Chinese military.

2. PayPal’s Locky wacky ransomware attack

This wouldn’t be the first time PayPal customers are duped into opening spoofed emails. In an article I wrote a while back, I pointed out that it’s a very common scamming tactic to send out bogus emails to PayPal account holders; usually, the buyers take the bite, but it can happen to sellers as well.

Anyway, as for the Locky ransomware email campaign, back in 2016, around 100 million Amazon customers woke up with their PayPal accounts hacked after opening an email which was reportedly sent by Amazon.

If you’re wondering about the email’s content, well, apparently, it had a generic, ‘Amazonesque’ text like “Your order has dispatched (sic!)” followed by a random code. However, if one was to scroll down a bit, he would have found that the email had a peculiar attachment: a word document. Sure, the attachments won’t bat an eye, since it’s only natural for an email to contain a doc detailing the transaction. Guess what happened if someone attempted to download and open the document?

3. RSA

This one’s a little ironic since it happened to a company that provides online security services. In 2011, a scammer sent forged emails to all employees. Of course, the spam filter identified flagged the message and sent it to where it belongs. Apparently, one overzealous employee stumbled upon the scam mail while searching through the spam folder. Unfortunately, that brief moment of weakness took a great toll on the company’s reputation. Guess who opened the malicious email?

4. Ubiquiti Networks Inc

Around 2015, several Ubiquiti Networks employees received emails from what appeared to be senior execs. As the story goes, the persons posing as managers asked their employees to funnel funds to a Hong Kong subsidiary, which was supposed to have been managed by a third party. Of course, the money never reached the subsidiary’s account since the emails were spoofed. An incident report indicates that the company lost about $40 million in the incident.

5. EFF (Electronic Frontier Foundation)

The same year, a group of scammers managed to distribute keyloggers and other malware, by tricking users into following an in-mail link which was reportedly sent by the Electronic Frontier Foundation. Of course, EFF got wind of the scam and managed to shut down the illegal op.

6. Epsilon

In 2011, Epsilon, one of the world’s leading data-driven marketing platform, had to face its “mid-life crisis”. Thousands of customers were tricked into opening spoofed emails linking to bogus websites, all of them laden with malware. At that time, reports revealed that the Epsilon spear phishing campaign might have been a diversion for a much larger operation. A subsequent analysis revealed that the malicious website downloaded malware in the background that could do anything from providing remote access to disabling antivirus software.

Any difference between regular phishing, spear phishing, and whale phishing?

Well, apart from the fact that it’s all about “the phishing”, yes, they’re certainly different. Think about it this way: phishing is like throwing a net, hoping to catch something; spear phishing’s like using a rod, and whale phishing is, well, like going full Ahab on someone.

Let’s elaborate: phishing is when you send out hundreds or thousands of spoofed emails, hoping that some unfortunate soul will open them, follow the link to the credential-grabbing website. Spear phishing, on the other hand, is where you add a dash of finesse to the whole scamming gig – no more flying in blind; you hit, grab, and scoot.

Keep in mind that high-profile targets are more likely to strike back compared to your regular working Joe. This means that he or she might have more resources available for investing in the hunt for the hunter.

There’s also the matter of scarcity or rather the frequency of each of the three types of attacks. As you probably know by now, email phishing’s boorishly common; chances are that there’s a spoofed email collecting dust in your spam folder as we speak.

Spear phishing attacks take some time to prepare and deploy, but they’re not that uncommon as one might think. Even with the above-mentioned ‘incidents’, that’s still a lot. The truth of the matter is that no one can say for sure how many successful spear phishing attacks have been so far considering that they’ve been around since the ‘90s.

Anyway, my giveaway to you is this: if it’s generic, then it’s simple phishing. If you one day fire up the work email and see an email from your boss telling you to transfer money to some off-shore gig, then it’s spear phishing. Last but not least, if you’re part of the upper-class and you receive a message begging you give, submit, or remit, then it’s whale phishing at its finest.

5 tips to avoid spear phishing attempts

Source: Mozilla

1. Continuous cybersecurity education

Remember that scene from the Conjuring movie where Lorraine says that knowing what evil is called gives you power over it? It’s the same with phishing. Nowadays, it’s really not enough to hire an entire IT department to take care of your company’s cybersecurity. There’s not much anyone can do if, say, one of your employees decides to pop open a suspicious email.

So, if you’re a business owner, turn cybersecurity ‘awareness’ into a routine; it doesn’t need to be that frequent. Once or twice per month is more than enough. Try using some printed handouts, perhaps even short video presentations. What’s the purpose of all of this? To teach your employees that opening suspicious email attachments is really not okay. You should also let them know the difference between regular phishing, rose phishing, and spear/whale phishing.

And don’t forget about the most important cybersecurity lesson: it only takes one weak link to make the entire chain break apart. Recall the Seagate affair? One misinformed HR officer sent the entire company in a downward spiral. Lesson learned!

If you’re a home user, you can always look out for new resources on how to better protect your devices. Check out our educational section for antimalware tips and tricks.

2. Deploy a professional antimalware/anti-fraud network. AI for the win.

I really don’t think that there’s anyone out there who would risk losing everything just because he doesn’t want to spend a couple of bucks on an antimalware solution. With companies, it’s a matter of upscaling and going pro all the way.

Most AM/AV suppliers offered tailored enterprise services. You should also keep in mind that signature-based antimalware solutions are obsolete, since they’re unable to compete with malicious loads backed up by rogue AIs.

So, if you’re looking to bolster your company’s cybersecurity, be sure to choose an AI-powered one. It’s even better if it employs heuristics search engines based on machine learning techniques. Remember that only a well-balanced AM/AV solution can protect you against online fraud attempts, spear phishing included.

The easy way to protect yourself against malware
Here's 1 month of Thor Foresight Home, on the house!
Use it to: Block malicious websites and servers from infecting your PC Auto-update your software and close security gaps Keep your financial and other confidential details safe


Try Thor Foresight

3. Stay on top of your email accounts

Probably the best way to safeguard your endpoints is to continuously monitor your accounts’ activity. Look if the spam filters are up and running and doing their job properly. If you see anything suspicious, don’t think twice before deleting or sending it to the spam folder. Doesn’t matter if you have a personal, business, work or work email account; any one of them can be hit by malware.

4. Full-throttle your DMARC

DMARC, which stands for Domain-based Message Authentication, Reporting, and Conformance is a sender/receiver protocol capable of figuring it if a message comes from a legit source or not. To deploy DMARC, you will need the Sender Policy Framework (the protocol that checks out email servers) and DomainKeys Identified Email (checks if the email has an embedded encryption key). Check with your AV/AM provider to see if your cybersecurity solution also covers DMARC standards.

5. Multi-factor auth whenever possible

If your company’s using several accounts, you should think about deploying multi-factor authentication solutions. Think Gmail’s 2FA. Yes, it may not be that Fort Knox-like security you were looking for, but an extra layer of protection doesn’t hurt. As for multi-factor auth, you can either go with digital tokenization or stick with physical keys just like Google’s Titan. Also, if you’re going to use 2FA from now on, you should definitely refrain from recycling passwords.


Any takeaways? Don’t get hooked – I think that’s perhaps the most important lesson one needs to learn. Keep in mind that scammers are always looking for ways to get to you, whether it’s through phishing, whaling or spear phishing. Do you have any interesting spear phishing stories to share? Shoot me a comment and let the games begin.

The post What Is Spear Phishing and How Do You Prevent It? appeared first on Heimdal Security Blog.